| Vulnerability Name: | CVE-2016-2417 (CCN-112100) | ||||||||||||||||
| Assigned: | 2016-02-01 | ||||||||||||||||
| Published: | 2016-02-01 | ||||||||||||||||
| Updated: | 2017-09-08 | ||||||||||||||||
| Summary: | media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474. | ||||||||||||||||
| CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.8 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C)
| ||||||||||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-2417 Source: CONFIRM Type: Vendor Advisory http://source.android.com/security/bulletin/2016-04-02.html Source: CONFIRM Type: UNKNOWN https://android.googlesource.com/platform/frameworks/av/+/1171e7c047bf79e7c93342bb6a812c9edd86aa84 Source: CCN Type: Google Security Research Issue 711 Android: Information Disclosure in IOMX getConfig/getParameter Source: XF Type: UNKNOWN android-iomx-cve20162417-info-disc(112100) Source: CCN Type: Packet Storm Security [04-09-2016] Android IOMX getConfig/getParameter Information Disclosure Source: CCN Type: Android Web site Nexus Security Bulletin—April 2016 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [04-11-2016] Source: EXPLOIT-DB Type: UNKNOWN 39685 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-2417 | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||